CVE-2006-2378
Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 34.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 34.79% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/ie · microsoft/internet explorer · microsoft/windows 2003 server · microsoft/windows xp
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/20605Vendor Advisory
- http://securitytracker.com/id?1016292
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=407
- http://www.kb.cert.org/vuls/id/923236Patch, US Government Resource
- http://www.osvdb.org/26432
- http://www.securityfocus.com/bid/18394Patch
- http://www.us-cert.gov/cas/techalerts/TA06-164A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/2320
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-022
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26809
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1590
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1640
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1668
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1756
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1866
- http://secunia.com/advisories/20605Vendor Advisory
- http://securitytracker.com/id?1016292
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=407
- http://www.kb.cert.org/vuls/id/923236Patch, US Government Resource
- http://www.osvdb.org/26432
- http://www.securityfocus.com/bid/18394Patch
- http://www.us-cert.gov/cas/techalerts/TA06-164A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/2320
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-022
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26809
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1590
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1640
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1668
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1756
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1866
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.